Fusion Is Not A Simple Ensemble! Towards The Evolving Views in Insider Threat Detection
Chengyu Song, Lin Yang, Jianming Zheng, Jingjing Zhang, Hongyu Kuang, Jinzhi Liao, Mengchun Zhao
Abstract
Insider threat detection (ITD) is notoriously difficult: malicious actions are rare, context-dependent, and deliberately hidden within massive volumes of legitimate user behavior. Existing ITD methods rely on single- or fused-view models, which lack extensibility and therefore fail to leverage the supervisory signals from newly introduced complementary views. While ensembling is a natural next step, its direct application to ITD confronts three core obstacles: scalability bottlenecks from independently trained sub - models, semantic misalignment across heterogeneous feature spaces, and view imbalance, where strong views overshadow weaker yet informative ones. In this work, we propose Insight-LLM, the first extensible multi-view fusion framework tailored for ITD. Insight-LLM encodes each view with frozen pre-trained backbones and aligns heterogeneous representations into a unified semantic space via a lightweight ViewAdapter, enabling coherent cross-view reasoning without incurring additional training overhead. A context-adaptive fusion module dynamically re-weights views to emphasize subtle yet semantically consistent threat signals, and the fused representation is integrated with task prompts for lightweight LLM fine-tuning. Experiments on CERT datasets show that Insight-LLM improves F1 by up to 4.8% and reduces false positives by 61%, while decreasing training time per newly added view by up to 83.2% compared with the simple Ensemble method.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e3aba6a5-491e-468c-a5c1-cf4a31735e63Related papers
- REACT: Residual-Adaptive Contextual Tuning for Fast Model Adaptation in Threat DetectionJiayun Zhang, Junshen Xu, Bugra Can, Yi FanWWW 2025 · 3 citations
- Unveiling Multi-View Anomaly Detection: Intra-view Decoupling and Inter-view FusionKai Mao, Yiyang Lian, Yangyang Wang, Meiqin Liu et al.AAAI 2025 · 4 citations
- Few-shot Multimodal Anomaly Detection via Dynamic Intra-modal Sparsity Attention and Quality-aware Cross-modal Fusion in Microservice SystemKaiqi Ding, Zijian Song, Kaigui BianKDD 2026
- ICAD-LLM: One-for-All Anomaly Detection via In-Context Learning with Large Language ModelsZhongyuan Wu, Jingyuan Wang, Zexuan Cheng, Yilong Zhou et al.AAAI 2026 · 1 citation
- Chimera: Harnessing Multi-Agent LLMs for Automatic Insider Threat SimulationJiongchi Yu, Xiaofei Xie, Qiang Hu, Yuhan Ma et al.NDSS 2026 · 11 citations
